Daily Dark Web
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
Daily Dark Web
No Result
View All Result
Home Ransomware News

Scania Hit By Alleged Ransomware Attack

August 5, 2025
Reading Time: 1 min read
scania

scania

The ransomware group known as TEAM XXX has allegedly targeted Scania, a major Swedish commercial vehicle manufacturer and a key part of the Volkswagen Group. Following the attack, the group began leaking files purportedly stolen from Scania’s insurance subdomain, claiming the company had denied the breach and refused to engage.

Scania, a global leader in transport solutions including trucks, buses, and industrial engines, is headquartered in Södertalje, Sweden. The incident highlights the growing trend of “double extortion” ransomware attacks, where cybercriminals not only encrypt a victim’s data but also exfiltrate it, threatening to publish the sensitive information online to pressure the company into paying the ransom. The ransomware group claimed on its leak site that it targeted a major vulnerability on the “insurance.scania.com” portal and decided to publish the data after the company “completely denied” that its systems were compromised.

The attackers’ post warned that “Important documents containing keys for the switches of those who have Clearance their vehicles were found in the files.” An initial review of the directory of leaked files suggests a wide range of potentially sensitive corporate and client information has been exposed. The titles of the leaked files include:

  • Dept G Corp Council files (.xls)
  • Factura (invoice) documents (.pdf)
  • Recovery payment documents (.pdf)
  • Transordizia RP files (.pdf)
  • Engine Specification documents (.doc)
  • CMR documents (.pdf)
Tags: AutomotiveCyberSecuritydata-leakdouble extortionransomwareScaniaswedenTEAM XXX
ShareTweet

Related Posts

Qilin Ransomware: Inspira, Muller, A&A, Longwood, Exclusive, Istarpal
Ransomware News

Qilin Ransomware: Inspira, Muller, A&A, Longwood, Exclusive, Istarpal

April 27, 2026
Narteks Tekstil A.S. Suffers Krybit Ransomware Attack
Ransomware News

Narteks Tekstil A.S. Suffers Krybit Ransomware Attack

April 27, 2026
Synmosa Biopharma Hit by Dragonforce Ransomware Attack
Ransomware News

Synmosa Biopharma Hit by Dragonforce Ransomware Attack

April 27, 2026
K2 Electric Inc Targeted in Genesis Ransomware Attack
Ransomware News

K2 Electric Inc Targeted in Genesis Ransomware Attack

April 22, 2026
Rutan & Tucker Law Firm Suffers Data Breach by Silentransomgroup
Ransomware News

Rutan & Tucker Law Firm Suffers Data Breach by Silentransomgroup

April 22, 2026
Qilin Breach: Sea Air, Kolin, INDCAR, PTS, Huonker, Ferguson, SEL, Sterimed, Avitrans, Rusk
Ransomware News

Qilin Breach: Sea Air, Kolin, INDCAR, PTS, Huonker, Ferguson, SEL, Sterimed, Avitrans, Rusk

April 22, 2026
Next Post
DEVMAN Ransomware Gang Targets Major Asian Travel Group Diethelm Travel and Brazilian Energy Firm Ruff

DEVMAN Ransomware Gang Targets Major Asian Travel Group Diethelm Travel and Brazilian Energy Firm Ruff

Major Brazilian Real Estate Firm Cibraco Allegedly Hit by Lynx Ransomware

Major Brazilian Real Estate Firm Cibraco Allegedly Hit by Lynx Ransomware

Recommended Stories

Pellenc Ransomware Attack: Alp-001 Group Claims Data Breach

Pellenc Ransomware Attack: Alp-001 Group Claims Data Breach

March 23, 2026
KaliHunt Groups Allegedly DDoS Attacks on US Airports and Baltic Countries

KaliHunt Groups Allegedly DDoS Attacks on US Airports and Baltic Countries

April 29, 2024
Cybercriminal Offers Access to Spanish Crypto Exchange’s Admin Panel for $10,000 in Monero

Cybercriminal Offers Access to Spanish Crypto Exchange’s Admin Panel for $10,000 in Monero

March 15, 2024

Popular Stories

  • SudamericaData Breach Exposes Over 1TB of Argentine Records

    SudamericaData Breach Exposes Over 1TB of Argentine Records

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    0 shares
    Share 0 Tweet 0
  • SUUMO, CHINTAI, At Home, HOME’S Suffer Data Breach

    0 shares
    Share 0 Tweet 0
  • Financial Tech Giant SilverLake Axis Allegedly Breached – 423GB of Data for Sale

    0 shares
    Share 0 Tweet 0
  • Telekom Serbia Investigates Leak of 160,000 Customer Records

    0 shares
    Share 0 Tweet 0
Daily Dark Web

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

No Result
View All Result
  • About Us
  • Home
  • Newsletter
  • Privacy Policy

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?